A 6-question self-assessment: gauge your data sovereignty and leave with recommendations.
A quick self-assessment (hosting, reversibility, AI, Cloud Act) that returns a sovereignty level and action points.
It is the organisation's ability to stay in control of its patient data: knowing where it is hosted, under which jurisdiction, who accesses it, and being able to retrieve it at any time. It rests on hosting, reversibility, access traceability and proper governance of subcontractors.
HDS certification mainly covers the hosting of health data entrusted to a third party, in France. It is a necessary foundation but not sufficient: sovereignty also depends on contractual reversibility, the actual localisation of processing (including AI), and the absence of dependence on a non-EU jurisdiction.
The Cloud Act is a US law that can let US authorities request access to data held by a provider under their jurisdiction, even if the servers are in Europe. Depending on such a provider creates a risk to patient data confidentiality.
Reversibility ensures you can retrieve all of your data in a usable format and switch providers without lock-in. Without an explicit clause, an organisation can become captive to a vendor, which weakens long-term control.
Approaches exist to train or run models without centralising raw data outside the organisation. The key is to verify where processing actually takes place and to document its localisation, rather than assuming AI necessarily means sending data abroad.
The EHDS (European Health Data Space) is an EU framework aimed at making health data easier to use and share, for care and research, with safeguards. It reinforces the value of structured, interoperable data hosted within the EU.